CVE-2010-3979 Information
Feb 14, 2021
cve
Description
Dswsbobje in SAP BusinessObjects Enterprise XI 3.2 generates different error messages depending on whether the Login field corresponds to a valid username which allows remote attackers to enumerate account names via a login SOAPAction to the dswsbobje/services/session URI.
Reference
http://spl0it.org/files/talks/source_barcelona10/Hacking20SAP20BusinessObjects.pdf
Share on: